Export Sessions to Excel Session Details Page

Viewing Additional Details for Investigation 6-7 4. Items to be added to the group are listed. To go back and change the items, click the Back button. To proceed with adding the items, click the Finish button.

6.6.2 Add to Group from Details Pages

To add a sessions parameter to a group: 1. Select a row containing one or more session parameters user, Device ID, IP, and so on.

2. Click the Add to Group button in the upper right corner.

The Add to Group dialog appears with the following search filters: 3. Select the group or create a new group. Figure 6–2 shows the dialog for adding a sessions parameter to an existing group. Table 6–4 Add to Group Dialog Filters Filter Description Group Name The name of the group. Groups for which the sessions parameter is not a member of are listed. Group Type The type of group. Groups for which the sessions parameter is not a member of are listed. Description The description of the group. Groups for which the session parameter is not a member of are listed. 6-8 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Figure 6–2 Add to Existing Group Figure 6–3 shows the dialog for creating a group to add a sessions parameter to. Viewing Additional Details for Investigation 6-9 Figure 6–3 Create a New Group to Add Sessions Parameter to Enter the following information to create a group: When adding a group to an existing group, data from selected rows of the type the group can accept are added to the group. If any data is already in the group, an informational message is displayed. When creating a group to add the entity to, do not leave any fields blank; otherwise, an error occurs.

4. Select Open this groups detail tab when done.

5. Click Add.

A confirmation dialog appears.

6. Click OK to dismiss the confirmation dialog.

6.7 Session Details Page

The Session Details page consolidates information needed for fraud analysis. To go to the Session Details page:

1. In the Search Results table, click the Session ID of the session of interest. The

Session Details page for that session is displayed. Table 6–5 Add to Group Fields Field Description Group Name The name of the group. Cache Policy Groups offer two Cache Policy options: Full Cache or None. By default, the Cache Policy should be set to all. For information, refer to Cache Policy . Group Type The type of group. Description Information about the group. 6-10 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager General details and all of the actions performed during the session are captured in the Session Details page. 2. View the details of the session.

6.8 Looking at Events from a Higher Level with Session Details

A Session Details page displays an overview of the events that transpired during a particular session for fraud analysis. It contains: ■ General session data points such as user, device, location, and other details ■ A forensic record of the session, including transactions and checkpoints that were evaluated. Each checkpoint displays the policies in that checkpoint, alerts that were triggered during the session for that checkpoint, and the final action for that checkpoint. The policy explorer view is also available to provide additional details about policies, rules, and conditions.

6.8.1 Policy Explorer

The Policy Explorer displays information about rules, conditions, trigger combinations, group linking, nested policies, and other items. Figure 6–4 Policy Explorer Rule Details Details about the rule is shown in the Policy Explorer. The session results display the scores and results of that rule. Viewing Additional Details for Investigation 6-11 Pre-conditions Pre-conditions for that rule is displayed in the details panel. The session results show the confidence factors and other values for the pre-conditions for that session. Conditions The values for the condition parameters are displayed. The session results show if the conditions returned true for this session evaluation. Trigger Combinations There is an option to view the triggered override combinations or view all overrides. Session results show the override information that was evaluated for this session including the nested policy information. Group Linking Group linking for the policy is displayed in the details panel.

6.8.2 Runtime Information

The Session Details page contains several panels. The main panels like checkpoints and transactions have multiple subpanels. Panel are not displayed if information is not available. Except for the Session Details panel, all other panels are displayed in the order of execution. Looking at the Session Details page, you can see the flow of events, the sequence when the events happened within the session. Figure 6–5 Session Details with Checkpoint, Alerts, Actions, and Policies

6.8.2.1 Session Details

The Session Details panel shows all the related information regarding the login transaction. It shows the authentication status, IP address from which the user logged in, user name, User ID, cookie information, autolearning processing status, and the login time. 6-12 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

6.8.2.2 Policies

A list of policies in that checkpoint are displayed in the Policies panel. You can view the rules and action that triggered. As an investigator, you are interested in why a particular rule triggered. For example, you might look at which policy and rules triggered the alert. Information can be gathered by looking at these details. For example, a user who successfully went through Pre-Authentication and Post-Authentication checkpoints knew the password and the questions and answers and there fore, there is a good chance that he is a valid user. On the other hand, a user who attempted to answer the questions twice and succeeded in providing a correct answer on his third attempt might be considered suspicious. This user did not know the answers right away so there is a chance that he may be a fraud trying out new answers. To view more details about the policy, you can launch the Policy Explorer using the icon on top of the panel or from any of the icons within the table. The policy link displays the Policy Details page and the rules link displays the Rule Details page. Only active and triggered rules are displayed. Only active policies are displayed. You have the option to view all the rules in the Policy Explorer. In the Policy Explorer, you can view the runtime values for each one of the policies and rules that were triggered. For example, if a rule triggered that showed that the user had logged in from a country that he did not usually log in from, you would want to look at the runtime details to see which country he logged in from. The Policy Explorer shows the policies that were triggered, the condition parameters, and the actual values.

6.8.2.3 Transactions

The Transactions panel displays a list of transactions that were created. You can view the actual transaction data and the entity attribute values used in the transactions. For example, a fraud investigator analyzing a session can see that a user was blocked performing a transaction and that a particular rule was triggered, and he can also see the amount that was passed in and the account number that was used in the transaction. Transactions can be created within a checkpoint or without an associating checkpoint. If a Transaction ID is not provided as in the case of a transaction without an associating checkpoint, OAAM processes the last transaction in the session. The Table 6–6 Policies in a Checkpoint Item Description Name The name of the policies that are under the checkpoint, rules under the policies, the conditions under the rules, and the action triggered. Status Executed for policies and Triggered for rules. Scoring Engine A scoring engine is provided at the policy level and at the checkpoint level. The policy scoring engine is applied to rule scores to determine the risk for each policy. Time The time of the occurrence. Weight Percentage value used to influence the total score. Score Level of risk that has been calculated for specific situations or parts of a situation, expressed as a number. There are multiple policies under one checkpoint. The scores of these policies are used to determine a score for the checkpoint.